On Fri, Jul 17, 2026 at 11:01:07AM +0000, [email protected] wrote: > > + /* 1 to 8 registers accessed at a time, within the same 8-reg group */ > > + while (nregs > 0) { > > + unsigned int reg_group = ALIGN_DOWN(regidx, 8); > > + unsigned int max_reg = min(regidx + nregs, reg_group + 8); > > [Severity: High] > Can reg_group + 8 overflow? Since regidx and reg_group are 32-bit unsigned > integers, if a caller passes a register index near the 32-bit maximum > (for example, 0xFFFFFFF8) and a small nregs value, reg_group + 8 will wrap > around to 0. > > If max_reg evaluates to 0, ndata becomes 0 - regidx, which can yield a value > larger than the original nregs. Will this cause out-of-bounds memory accesses > on the regs buffer when passed to cla_op_launch(), and an infinite loop due to > underflowing nregs?
We do need to be careful about regidx overflow since all 32 bits are valid in CLA (custom accel range is 0x00100000-0xffffffff). I'll make it u64 in this function
